An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-08-03T00:00:00
Updated: 2024-10-17T20:05:38.922Z
Reserved: 2023-03-15T00:00:00
Link: CVE-2023-28468
Vulnrichment
Updated: 2024-08-02T12:38:25.284Z
NVD
Status : Modified
Published: 2023-08-03T15:15:20.167
Modified: 2024-11-21T07:55:09.023
Link: CVE-2023-28468
Redhat
No data.